6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25595
jetAudio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-469 1 PoC

jetAudio 8.1.7.20702 Basic contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string through the URL input handler. Attackers can trigger the crash by pasting a buffer of 5000 characters into the Open URL dialog, causing the application to terminate abnormally.

CVE-2019-25569
RealTerm: Serial Terminal General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overflow vulnerability in the Echo Port field that allows local attackers to crash the application by triggering a structured exception handler (SEH) chain corruption. Attackers can craft a malicious input string with 268 bytes of padding followed by SEH overwrite values and paste it into the Port field to cause denial of service.

CVE-2019-25623
Luminance Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-641 1 PoC

Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arbitrary character sequences and trigger the application to process the input, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25617
Ease Audio Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 2 PoCs

Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows local attackers to crash the application by processing malformed MP4 files. Attackers can create a crafted MP4 file containing an oversized buffer and load it through the Audio Cutter interface to trigger an application crash.

CVE-2019-25572
NordVPN Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1260 1 PoC

NordVPN 6.19.6 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the email input field. Attackers can paste a buffer of 100,000 characters into the email field during login to trigger an application crash.

CVE-2019-25660
LanHelper General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

LanHelper 1.74 contains a local buffer overflow vulnerability that allows attackers to crash the application by sending excessively long input strings. Attackers can exploit the Form Send Message feature by pasting 6000 bytes of data into the Message text field to trigger a denial of service condition.

CVE-2019-25484
WinMPG iPod Convert General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

WinMPG iPod Convert 3.0 contains a buffer overflow vulnerability in the Register dialog that allows local attackers to crash the application by supplying an oversized payload. Attackers can paste a large string of characters into the User Name and User Code field to trigger a denial of service condition.

CVE-2019-25653
Navicat for Oracle Database
6.9
MEDIUM
EPSS
0.0%
2019 CWE-620 1 PoC

Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer of 550 repeated characters into the password parameter during Oracle connection configuration to trigger an application crash.

CVE-2019-25485
R Windows
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the GUI Preferences language menu field that allows local attackers to bypass DEP and ASLR protections. Attackers can inject a crafted payload through the Language for menus preference to trigger a structured exception handler chain pivot and execute arbitrary shellcode with application privileges.

CVE-2019-25599
Backup Key Recovery General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-466 1 PoC

Backup Key Recovery 2.2.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 or more characters into the Name field during registration to trigger a crash when submitting the form.

CVE-2019-25665
River Past Ringtone Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to activation fields. Attackers can paste 300 bytes of data into the Email textbox and Activation code textarea via the Help menu's Activate dialog to trigger a denial of service condition.

CVE-2019-25659
ASPRunner Professional General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash.

CVE-2019-25620
Tree Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-168 1 PoC

Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25463
SpotIE Internet Explorer Password Recovery General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a buffer overflow and crash the application.

CVE-2019-25476
Outlook Password Recovery Denial of Service Exploit General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and Registration Code field to trigger a denial of service condition.

CVE-2019-25597
NSauditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function to cause a denial of service condition.

CVE-2019-25545
Terminal Services Manager General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing a denial of service when the server entry is accessed.

CVE-2019-25546
NetAware General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by pasting a 1000-byte buffer into the Share Name parameter when adding a new share through the Manage Shares interface.

CVE-2019-25469
Folder Lock General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Folder Lock 7.7.9 contains a buffer overflow vulnerability in the serial number registration field that allows local attackers to crash the application by submitting an oversized payload. Attackers can paste a 6000-byte buffer of arbitrary data into the 'Serial Number and Registration Key' field to trigger a denial of service condition.

CVE-2019-25558
Selfie Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Selfie Studio 2.17 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a large string of characters into the New Width or New Height field to trigger a buffer overflow that crashes the application.